INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters and Qilin Target Real Estate Giant via Vishing

| 2026-05-05 13:34 HIGH LOW DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A data breach occurred at Cushman & Wakefield on May 1, 2026, when two cybercrime groups, ShinyHunters and Qilin, claimed responsibility for the attack. The incident was reportedly a result of vishing (voice phishing), with an employee being socially engineered into divulging sensitive information. As a result, over 500,000 Salesforce records containing personally identifiable information (PII) were stolen. Cushman & Wakefield activated its response protocols and engaged third-party expert advisors to support the investigation. The attack was later confirmed by ShinyHunters, which claimed it had stolen the data before setting a May 6 deadline for C&W to make contact or risk further leakage.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/05/05
ShinyHunters claimed to have stolen over 500,000 Salesforce records containing PII and other internal corporate data through vishing.
data_breach 500,000 Salesforce records
Tactical Metrics
Metrics
data_breach
500,000
Salesforce Records
Intelligence Sources